CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,429 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
150,522 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-1468 EXP | Buffer overflow in errpt in AIX 4.3.3 allows local users to execute arbitrary code as root. | Patch early | 10.0 high | 4.1% | 2003-04-22 |
| CVE-2016-7980 EXP | Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack the authent… | Patch early | 8.8 high | 4.1% | 2017-01-18 |
| CVE-2002-0525 EXP | Format string vulnerabilities in (1) inews or (2) rnews for INN 2.2.3 and earlier allow local users and remote malicious NNTP servers to gain privileg… | Patch early | 10.0 high | 4.1% | 2002-08-12 |
| CVE-2006-5223 EXP | PHP remote file inclusion vulnerability in includes/functions_user_viewed_posts.php in the Nivisec User Viewed Posts Tracker module 1.0 and earlier fo… | Patch early | 7.5 high | 4.1% | 2006-10-10 |
| CVE-2018-4230 EXP | An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "NVIDIA Graphics Drivers" component. It al… | Patch early | 7.0 high | 4.1% | 2018-06-08 |
| CVE-2004-0621 EXP | admin.php in Newsletter ZWS allows remote attackers to gain administrative privileges via a list_user operation with the ulevel parameter set to 1 (ad… | Patch early | 10.0 high | 4.1% | 2004-12-06 |
| CVE-2008-7115 EXP | The web interface to the Belkin Wireless G router and ADSL2 modem F5D7632-4V6 with firmware 6.01.08 allows remote attackers to bypass authentication a… | Patch early | 10.0 high | 4.1% | 2009-08-28 |
| CVE-2007-1372 EXP | PHP remote file inclusion vulnerability in styles/internal/header.php in the PostGuestbook 0.6.1 module for PHP-Nuke allows remote attackers to execut… | Patch early | 10.0 high | 4.1% | 2007-03-10 |
| CVE-2000-0638 EXP | bb-hostsvc.sh in Big Brother 1.4h1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the HOSTSVC parameter. | Patch early | 10.0 high | 4.1% | 2000-07-11 |
| CVE-2000-1074 EXP | csstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could allow the icsuser account to ga… | Patch early | 10.0 high | 4.1% | 2000-12-11 |
| CVE-2004-2158 EXP | SQL injection vulnerability in Serendipity 0.7-beta1 allows remote attackers to execute arbitrary SQL commands via the entry_id parameter to (1) exit.… | Patch early | 7.5 high | 4.1% | 2004-12-31 |
| CVE-2000-0675 EXP | Buffer overflow in Infopulse Gatekeeper 3.5 and earlier allows remote attackers to execute arbitrary commands via a long string. | Patch early | 7.5 high | 4.1% | 2000-07-13 |
| CVE-2002-1242 EXP | SQL injection vulnerability in PHP-Nuke before 6.0 allows remote authenticated users to modify the database and gain privileges via the "bio" argument… | Patch early | 7.5 high | 4.1% | 2002-11-12 |
| CVE-2007-2201 EXP | Multiple PHP remote file inclusion vulnerabilities in Post Revolution 6.6 and 7.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL i… | Patch early | 7.5 high | 4.1% | 2007-04-24 |
| CVE-2007-2657 EXP | Unspecified vulnerability in the PrecisionID Barcode 1.3 ActiveX control in PrecisionID_DataMatrix.DLL allows remote attackers to cause a denial of se… | Patch early | 7.8 high | 4.1% | 2007-05-14 |
| CVE-2006-4632 EXP | Multiple SQL injection vulnerabilities in SoftBB 0.1, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) group… | Patch early | 7.5 high | 4.1% | 2006-09-08 |
| CVE-2019-10716 EXP | An Information Disclosure issue in Verodin Director 3.5.3.1 and earlier reveals usernames and passwords of integrated security technologies via a /int… | Patch early | 7.7 high | 4.1% | 2019-10-21 |
| CVE-2006-3819 EXP | Eval injection vulnerability in the configure script in TWiki 4.0.0 through 4.0.4 allows remote attackers to execute arbitrary Perl code via an HTTP P… | Patch early | 7.5 high | 4.1% | 2006-07-27 |
| CVE-2016-1914 EXP | Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Service befor… | Patch early | 8.8 high | 4.1% | 2017-04-13 |
| CVE-2008-5197 EXP | SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the lid parameter in a deta… | Patch early | 7.5 high | 4.1% | 2008-11-21 |
| CVE-2007-2736 EXP | PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config_at… | Patch early | 10.0 high | 4.1% | 2007-05-17 |
| CVE-2006-2400 EXP | The leetnet functions (leetnet/rudp.cpp) in Outgun 1.0.3 bot 2 and earlier allow remote attackers to cause a denial of service (game interruption) via… | Patch early | 7.8 high | 4.1% | 2006-05-16 |
| CVE-2006-2401 EXP | The leetnet functions (leetnet/rudp.cpp) in Outgun 1.0.3 bot 2 and earlier allow remote attackers to cause a denial of service (application crash) via… | Patch early | 7.8 high | 4.1% | 2006-05-16 |
| CVE-2000-0757 EXP | The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privileges by connecting to the serv… | Patch early | 10.0 high | 4.1% | 2000-10-20 |
| CVE-2008-4502 EXP | Multiple PHP remote file inclusion vulnerabilities in DataFeedFile (DFF) PHP Framework API allow remote attackers to execute arbitrary PHP code via a… | Patch early | 10.0 high | 4.1% | 2008-10-09 |
| CVE-2005-3817 EXP | Multiple SQL injection vulnerabilities in Softbiz Web Host Directory Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands v… | Patch early | 7.5 high | 4.1% | 2005-11-26 |
| CVE-2021-24581 EXP | The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting in a page, leading to a Stored… | Patch early | 8.8 high | 4.1% | 2021-08-30 |
| CVE-2006-0681 EXP | Format string vulnerability in powerd.c in Power Daemon (powerd) 2.0.2 and earlier allows remote attackers to execute arbitrary code via format string… | Patch early | 7.5 high | 4.1% | 2006-02-15 |
| CVE-2007-3340 EXP | BugHunter HTTP SERVER (httpsv.exe) 1.6.2 allows remote attackers to cause a denial of service (application crash) via a large number of requests for n… | Patch early | 7.8 high | 4.1% | 2007-06-21 |
| CVE-2004-1552 EXP | SQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page… | Patch early | 7.5 high | 4.1% | 2004-12-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt